Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-66773
  • github.com/sap/python-pyodata
Server-controlled `__next` URL is not checking cross-origin 22 hours ago
  • No fix available
  • Severity - 5.9 (Medium)
CVE-2026-11812
  • github.com/zephyrproject-rtos/zephyr
UpdateHub: race condition on shared context causes out-of-bounds write and DoS 23 hours ago
  • No fix available
  • Severity - 2.5 (Low)
CVE-2026-11811
  • github.com/zephyrproject-rtos/zephyr
Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS 23 hours ago
  • Fix available
  • Severity - 3.7 (Low)
CVE-2026-8718
  • github.com/zephyrproject-rtos/zephyr
Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID_VALUE`) in Zephyr net sockets/TLS 23 hours ago
  • Fix available
  • Severity - 8.4 (High)
CVE-2026-72919
  • github.com/rocketchat/rocket.chat
Rocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into Teams yesterday
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-72918
  • github.com/rocketchat/rocket.chat
Rocket.Chat: Insecure implementation of websocket notifications yesterday
  • Fix available
  • Severity - 5.4 (Medium)
CVE-2026-72916
  • github.com/mastodon/mastodon
Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 Addresses yesterday
  • Fix available
  • Severity - 6.3 (Medium)
CVE-2026-72915
  • github.com/mastodon/mastodon
Mastodon: Personally-identifying information disclosure due to incorrect access control validation yesterday
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-72914
  • github.com/mastodon/mastodon
Mastodon: Exhausting data by an unauthenticated request to the admin retention API yesterday
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-72913
  • github.com/kovidgoyal/kitty
Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences yesterday
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-72912
  • github.com/gchq/cyberchef
CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL yesterday
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-72911
  • github.com/frappe/erpnext
ERPNext: Possibility of server-side template injection due to missing validation yesterday
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-72910
  • github.com/frappe/erpnext
ERPNext: Unauthorised modification of master data due to missing validation yesterday
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-72909
  • github.com/frappe/erpnext
ERPNext: Broken Access Control on certain endpoints yesterday
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-72908
  • github.com/frappe/erpnext
ERPNext: Possibility of SQL injection due to missing validation yesterday
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-72907
  • github.com/frappe/erpnext
ERPNext: Broken Access Control on certain endpoint yesterday
  • Fix available
  • Severity - 6.5 (Medium)